Executive brief
Microsoft Azure Stack Edge, a cloud-managed computing appliance used for processing data at the network edge, is vulnerable to a security flaw that allows an attacker to perform spoofing. By exploiting this vulnerability, an authorized user could trick other users into performing unintended actions or reveal sensitive information by manipulating web content. This could lead to a compromise of the management interface and impact the integrity of operations on the device.
Technical details
A stored or reflected cross-site scripting (XSS) vulnerability exists in Microsoft Azure Stack Edge due to improper neutralization of input during web page generation. An attacker with high privileges (PR:H) can exploit this over the network by injecting malicious scripts into the management interface. Successful exploitation requires a victim to interact with the affected page (UI:R), leading to a scope change (S:C) that allows the attacker to execute arbitrary code in the context of the victim's browser session. This can result in full loss of confidentiality, integrity, and availability for the affected component.
Affected products
- Microsoft Azure Stack Edge
Timeline
- 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.